CVE Vulnerabilities

CVE-2019-11514

Incomplete Cleanup

Published: Apr 25, 2019 | Modified: Aug 24, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Flarum Flarum 0.1.0 (including) 0.1.0 (including)
Flarum Flarum 0.1.0-beta (including) 0.1.0-beta (including)
Flarum Flarum 0.1.0-beta2 (including) 0.1.0-beta2 (including)
Flarum Flarum 0.1.0-beta3 (including) 0.1.0-beta3 (including)
Flarum Flarum 0.1.0-beta4 (including) 0.1.0-beta4 (including)
Flarum Flarum 0.1.0-beta5 (including) 0.1.0-beta5 (including)
Flarum Flarum 0.1.0-beta6 (including) 0.1.0-beta6 (including)
Flarum Flarum 0.1.0-beta7 (including) 0.1.0-beta7 (including)
Flarum Flarum 0.1.0-beta7.1 (including) 0.1.0-beta7.1 (including)
Flarum Flarum 0.1.0-beta7.2 (including) 0.1.0-beta7.2 (including)

Potential Mitigations

References